A warning said if AI starts rapidly reducing software security flaws, hacking tools used by governments for criminal investigations and surveillance could weaken. [Photo: Shutterstock]

[DigitalToday Jin-ho Lee] The government said last year it would inspect security vulnerabilities in 1,650 IT systems, but it did not separately verify the results of self-checks submitted by private companies, it has emerged.

Data obtained by Lee Jeong-heon (이정헌), a lawmaker from the Democratic Party and a member of the National Assembly's Science, ICT, Broadcasting and Communications Committee, showed that the Ministry of Science and ICT collected only documents confirming whether vulnerability checks were conducted when it carried out emergency security inspections of private companies last year. It did not receive details of the vulnerabilities the companies found.

The government announced a "whole-of-government comprehensive information protection package" in October last year and said it would inspect security vulnerabilities in 1,650 IT systems at public institutions and financial firms, as well as telecom and platform companies. Of those, 949 were companies certified under the Information Security Management System (ISMS).

The ministry explained that because company-by-company vulnerability information is sensitive, it did not collect it separately and had companies manage it themselves. But Lee pointed out that some companies that replied they had completed the checks later had personal data leaks and security incidents this year. Eight companies, including Musinsa and Weverse Company, S-OIL TotalEnergies Lubricants and SSG.com, were included in last year's inspection targets and replied "inspection completed."

Among them, 29CM, operated by Musinsa, had personal information on about 160,000 customers leaked, and Weverse, run by Weverse Company, had more than 400,000 cases of personal information leaked. S-OIL TotalEnergies Lubricants and SSG.com also detected abnormal signs in September and reported security incidents to KISA.

Lee said the government's security inspection ultimately ended with companies "self-checking". He said the government should establish an objective pre-verification system and strengthen follow-up management and oversight rather than rely on formal self-inspections.

Keyword

#Ministry of Science and ICT #KISA #ISMS #Musinsa #Weverse
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.